
Fake FIFA Ticket Sites Steal Cards and OTPs
Researchers and the FBI warn that criminals are luring World Cup fans to convincing fake FIFA ticket websites, often via social media ads and shared links. The…
Researchers tracked a large scam wave abusing interest in the 2026 FIFA World Cup, including fake merchandise stores, cloned ticket sites, and bogus “free streaming” pages. The most harmful scams used near-perfect ticket-site clones to steal login details, credit card data, and one-time passwords in real time to push through fraudulent payments. Users were commonly pulled in via search results manipulated by SEO poisoning, then redirected through multiple pages to scam destinations.
Researchers tracked more than 35,000 malicious or suspicious World Cup related sites between January and June 2026, with a large share of visits coming from Japan. The scam wave spanned three main categories: counterfeit merchandise shops, cloned ticket and hospitality sites, and fake live-streaming pages. Each category relied on a slightly different lure, but all of them depended on getting a fan to click a link outside the official channel.
The most damaging variant was the cloned ticket site. These pages nearly perfectly replicated an official FIFA hospitality and ticket purchase experience. Victims entered an email and password, which went straight to the attackers, then supplied credit card details. At the final step, the fake site prompted the user to enter a one-time password on its own payment screen. That let attackers use the OTP in real time to push through a fraudulent charge, defeating protections like 3-D Secure that are designed to stop exactly this kind of fraud.
A major factor was SEO poisoning. Searches for phrases like free World Cup streaming or FIFA merchandise were manipulated so scam pages ranked highly in search results. Clicking through often carried the victim across a chain of relay pages hosted on blogging platforms before landing on the final fake site, making the path harder to trace back to a single source. The scarcity and excitement around a major event like the World Cup also pushed people to move quickly rather than verify the site first.
The clearest defense is navigating directly to official ticket, merchandise, and streaming sites rather than clicking search or social ad links. Treat words like free and official with skepticism, especially around streaming offers. Before entering any one-time password, confirm the merchant and amount match the intended purchase, and stop immediately if anything looks off. Using a unique password for every service also limits the damage if credentials are captured by a lookalike site, since a single stolen password should not be able to unlock other accounts.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The cloned sites harvested credit card details and then prompted victims to enter the one-time password directly on the fake payment screen, letting attackers use it in real time to complete fraudulent charges even when 3-D Secure was in place.
Many users found the scam sites through manipulated search results, a technique known as SEO poisoning, and were then redirected through relay pages hosted on blogging platforms before landing on the fake destination.
Red flags include being asked to enter an OTP on a merchant page instead of a bank verification flow, prompts claiming registration is required to watch a stream, and too-good-to-be-true pricing or availability.
They should verify that the merchant and amount match their actual purchase, and if anything looks off, stop without entering the code and contact their card company or bank directly.
In 2026, over thirty‑five thousand fake World Cup sites popped up, some look exactly like the real FIFA ticket page. You land on a site that almost completely replicates the official FIFA hospitality page. It asks you to log in, enter your card, then type the one‑time password on its own payment screen, while it pushes through a real charge in the background. Same play with streaming: you search 'fifa ワールドカップ 2026 無料配信', click a top result, bounce through a few pages, land on a fake broadcaster with a video that never plays, only 'registration required to watch' and a credit card form. Here’s the move: for World Cup tickets, merch, or streams, never trust search results or ads, type the official site address yourself and only enter an OTP in your bank’s own verification screen.

Researchers and the FBI warn that criminals are luring World Cup fans to convincing fake FIFA ticket websites, often via social media ads and shared links. The…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Researchers reported a real spearphishing campaign that impersonates DocuSign emails to trick tech executives into clicking “Review Document” links and…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Researchers reported a real phishing campaign targeting Call of Duty Mobile players with a fake “free Call of Duty Points” giveaway site. Victims are tricked…

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…